Collected every two hours from specialised publications — each link leads to the original article.
Catalyst::Plugin::Static::Simple for Perl sets the Cache‑Control header to "public" for every static asset served. Consequently, intermediaries such as shared …
Multiple vulnerabilities were discovered in lxml, a set pythonic binding for the libxml2 and libxslt libraries, which may lead to information disclosure or pri…
Several security issues were fixed in LXC.
An update that solves 8 vulnerabilities and has 12 bug fixes can now be installed.
An update that solves seven vulnerabilities can now be installed.
An update that solves four vulnerabilities can now be installed.
An update that solves six vulnerabilities and has one security fix can now be installed.
An update that solves 662 vulnerabilities, contains two features and has 35 security fixes can now be installed.
An update that solves four vulnerabilities can now be installed.
Moderate: .NET 8.0 security, bug fix, and enhancement update
An update that solves eight vulnerabilities and has one fix can now be installed.
An update that solves one vulnerability can now be installed.
An update that solves five vulnerabilities and has one fix can now be installed.
fix HTTP/2 stream-dependency tree UAF (CVE-2026-10536) fix stale proxy password leak (CVE-2026-9079) fix wrong reuse for different services (CVE-2026-8458)
Fix HTTP/2 stream-dependency tree UAF (CVE-2026-10536) Fix Native CA trust persist (CVE-2026-11564) Fix stale proxy password leak (CVE-2026-9079) Fix wrong reu…
Beets could allow malicious media metadata to compromise its web interface.
An update that solves eight vulnerabilities and has one fix can now be installed.
When an authentication platform goes down, downstream applications go with it. Employees can't sign in, customers get locked out, and scheduled jobs quietly fa…
A security update for helm addresses three vulnerabilities, including privilege escalation and credential exfiltration issues, with a critical CVSS score of 9.…
Multiple vulnerabilities in the Caddy web server can lead to unauthorized access and other security issues; users are urged to upgrade to version 2.6.2-12+deb1…
Multiple vulnerabilities in the Icinga 2 monitoring system could lead to denial of service, information disclosure, privilege escalation, or the compromise of …
Multiple vulnerabilities in WebKitGTK have been identified, leading to process crashes, memory corruption, and potential data leaks; users are urged to upgrade…
An update that has one security fix can now be installed.
1.033 - CVE-2026-14454: Fix mishandling of large EXIF IFD entry count values — treated as negative numbers, could lead to allocation failure and program exit -…